1. Overview
GiftMi (“we,” “us,” or “our”) operates the website giftmi.in (the “Service”) that allows verified Instagram creators to publish public wishlists and receive gifts from their fans. This policy describes our practices regarding the collection, use, and disclosure of your information in connection with your use of the Service.
By using GiftMi, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
From Creators
- Instagram account information (via Instagram Business Login) — see Section 3 below for details.
- Account details: email address, password (hashed using bcrypt), phone number, first and last name.
- Shipping address: recipient name, phone, street address, city, state, pincode, country. Stored encrypted using AES-256-CBC.
- Wishlist content: product URLs, titles, images, prices, and personal notes you publish.
- Thank-you notes: messages you send to fans after receiving gifts.
From Fans
- Account details: email, first/last name, phone number, password (set after first gift).
- Billing address: collected at checkout for each order, stored encrypted with AES-256-CBC and snapshotted on the order record.
- Payment information:processed entirely by Razorpay. We do not store card numbers, CVVs, or UPI PINs. We store only the Razorpay payment ID, order ID, and payment method type (e.g., “upi”, “card”).
- Gift messages: optional message you may attach to a gift, visible to the recipient creator.
- Sender preferences: whether to display your gift as Anonymous, with a Nickname, or with your real name.
Collected Automatically
- Profile view analytics: we hash visitor IP + user agent + day + creator ID using SHA-256 to deduplicate visits to one per day per visitor per creator. We do not store raw IP addresses or set tracking cookies for analytics.
- Session cookies: for authentication (JWT access + refresh tokens stored in HttpOnly cookies).
- Technical logs: standard server logs (IP address, user agent, timestamps) retained for up to 30 days for security and debugging.
3. Instagram Data
When you sign up as a creator, GiftMi uses Instagram's Business Login API (with the instagram_business_basic permission) to verify your identity and display your public profile. We collect and store:
- Instagram User ID — unique numeric identifier used to prevent duplicate accounts.
- Username — your @handle.
- Display name — shown on your public GiftMi profile.
- Profile picture URL — shown as your avatar.
- Follower count — used to verify the 10,000 follower minimum.
- Following count and media count — used for aggregate analytics only.
- Account type (Personal/Creator/Business) — used to verify Creator or Business account requirement.
- Long-lived access token — encrypted at rest, used to refresh your profile data periodically.
We do NOT access: your Instagram posts, stories, reels, direct messages, comments, followers list, or following list. We do not post on your behalf.
You can revoke GiftMi's access at any time via Instagram Settings → Apps and Websites → Active. Upon revocation, your access token is automatically deleted from our systems via Instagram's deauthorize callback.
4. How We Use Information
- Provide the Service — display creator profiles, process gift orders, deliver products to creators.
- Verify identity — confirm creators own their claimed Instagram handle and meet eligibility requirements.
- Process payments — via Razorpay, our payment gateway partner.
- Send transactional emails — order confirmations, shipping updates, thank-you notes, password resets. Sent via AWS SES.
- Show analytics to creators — total profile visits and gift counts (no personal information about visitors).
- Prevent fraud and abuse — detect duplicate accounts, suspicious activity, and payment fraud.
- Comply with legal obligations — Indian tax law, accounting, and regulatory requirements.
6. Storage & Security
- Encryption at rest: All address fields (shipping addresses, billing addresses, and order billing snapshots) are encrypted using AES-256-CBC before storage.
- Encryption in transit: All connections to GiftMi use HTTPS/TLS 1.2 or higher.
- Password security: Passwords are hashed using bcrypt with a strong cost factor. We never store plaintext passwords.
- Database location: PostgreSQL hosted in India.
- Access control: Only authorized Velnir Tech personnel have access to production systems, on a need-to-know basis.
- Data retention: We retain personal information only as long as needed to provide the Service and comply with legal obligations. Order records are retained for 7 years per Indian tax law (with personal identifiers anonymized after account deletion).
7. Your Rights
You have the right to:
- Access the personal information we hold about you (via your Profile page).
- Correct inaccurate information (via your Profile page).
- Delete your account and associated data — see our Data Deletion page.
- Withdraw consent for Instagram data processing by disconnecting GiftMi from your Instagram account.
- Export your data — email us at contact@giftmi.in for a copy of your data.
- File a complaintwith India's Data Protection Authority if you believe your rights have been violated.
9. Children's Privacy
GiftMi is not intended for users under 18 years of age. We do not knowingly collect information from children under 18. If you believe a child has provided us with information, please contact us at contact@giftmi.in and we will delete it promptly.
10. International Transfers
Our servers are located in India. If you access GiftMi from outside India, your information may be transferred to and processed in India. By using our Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (if you have an account) or by posting a notice on giftmi.in. The “Effective Date” at the top of this page indicates the latest revision.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact us at: